Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,906 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Privacy Commissioner for Personal Data (PCPD), Hongkong – 0 % · 2 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
2 cases
23 Apr 2026 Yau Yat Chuen Garden City Club LimitedRansomware via remote maintenance access: enforcement notice against private club Order
In a ransomware attack on the membership management system of Yau Yat Chuen Garden City Club Limited, a private, non-profit recreational club, reported on 31 October 2025, data of 9,045 current and former members and supplementary card holders were affected, including identity card or passport numbers. The attacker exploited a known vulnerability in outdated remote access software of the external service provider and reached the server, which had been left logged in, without further authentication; antivirus software and firewall were outdated, and personal data had been kept longer than necessary. In its investigation report published on 23 April 2026 the PCPD (Privacy Commissioner for Personal Data, Hong Kong's data protection authority) found breaches of DPP 4(1) and DPP 2(2) and served an enforcement notice.
Service providers' remote maintenance access belongs in an organisation's own security concept: current software, additional authentication and no servers left permanently logged in.
Service providers' remote access, patch management and retention periods
- Authority / court
- Privacy Commissioner for Personal Data (PCPD), Hongkong
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Data (Privacy) Ordinance, Data Protection Principles 4(1) und 2(2); Enforcement Notice
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 23 Apr 2026
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
21 Aug 2025 Kwong's Art Jewellery Trading Company Limited, My Jewelry Management LimitedJewellery companies: data of around 79,400 people stolen – enforcement notices Order
At Kwong's Art Jewellery Trading Company Limited and its retail subsidiary My Jewelry Management Limited, which run their IT systems jointly, an attacker (reported in November 2024) obtained the credentials of an administrator account by brute force, exfiltrated the database and deleted it; around 79,400 individuals were affected, including customers and current and former employees. In its report published on 21 August 2025 the PCPD (Privacy Commissioner for Personal Data, Hong Kong's data protection authority) found breaches of DPP 4(1), among other things because the account of a departed employee had not been deleted in time, server operating systems were outdated and security policies and security assessments were lacking. Both companies were served enforcement notices to remedy the deficiencies and prevent further contraventions.
Delete the accounts of departing staff immediately, keep servers up to date and protect administrator access against brute-force attacks.
Access management for leavers, patch management and protection of administrator accounts
- Authority / court
- Privacy Commissioner for Personal Data (PCPD), Hongkong
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Data (Privacy) Ordinance, Data Protection Principle 4(1); Enforcement Notices
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 21 Aug 2025
Checked against the official source on 3 Oct 2026 · Direct link